CVE Vulnerabilities

CVE-2011-3628

Published: Apr 15, 2014 | Modified: Apr 16, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1.1.3-2ubuntu2.1 on Ubuntu 11.10, before 1.1.2-2ubuntu8.4 on Ubuntu 11.04, before 1.1.1-4ubuntu2.4 on Ubuntu 10.10, before 1.1.1-2ubuntu5.4 on Ubuntu 10.04 LTS, and before 0.99.7.1-5ubuntu6.5 on Ubuntu 8.04 LTS, when using certain configurations such as session optional pam_motd.so, allows local users to gain privileges by modifying the PATH environment variable to reference a malicious command, as demonstrated via uname.

Affected Software

Name Vendor Start Version End Version
Libpam-modules Canonical 0.9.7 0.9.7
Libpam-modules Canonical 1.1.1 1.1.1
Libpam-modules Canonical 1.1.2 1.1.2
Libpam-modules Canonical 1.1.3 1.1.3
Ubuntu_linux Canonical 8.04 8.04
Ubuntu_linux Canonical 10.04 10.04
Ubuntu_linux Canonical 10.10 10.10
Ubuntu_linux Canonical 11.04 11.04
Ubuntu_linux Canonical 11.10 11.10
Pam Ubuntu devel *
Pam Ubuntu lucid *
Pam Ubuntu maverick *
Pam Ubuntu natty *
Pam Ubuntu oneiric *

References